I am doing some initial testing and have my Astaro boxes WAN hooked into my LAN. I only have the management NIC plugged into the network.
I noticed that I have 419 dropped DNS packets going to 192.36.148.17.
inetnum: 192.36.148.0 - 192.36.148.255
netname: I-ROOTSERVER
descr: Special net for DNS i.root-servers.net.
country: SE
Why would it be dropping these? In fact, why would it even see any DNS traffic on this interface since everything is on a switch? Only my IPCOP box should be getting any DNS traffic.
I am also seeing blocks going out to Veri Sign.
OrgName: VeriSign Global Registry Services
OrgID: VGRS
Address: 21345 Ridgetop Circle
City: Dulles
StateProv: VA
PostalCode: 20166
Country: US
NetRange: 192.58.128.0 - 192.58.128.255
CIDR: 192.58.128.0/24
And to my IPCOP box.
I am also seeing IGMP broadcast packets that are being blocked. 224.0.0.1. I have no idea why I am seeing multicast packets!
What is going on? The blocked out IP is my IPCOP box.
C68